Home > SearchSecurity.com's Web Security School
Security School:
EMAIL THIS

SearchSecurity.com's Web Security School

08 Jun 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Welcome to SearchSecurity.com's Web Security School, where you'll learn how to harden a Web server and apply countermeasures to prevent hackers from breaking into a network. Study at your own pace and learn how to implement security policies and test a Web site's security, as well as how to handle a breach should the unspeakable happen. Guest instructor Michael Cobb will also arm you with tactics for creating a human firewall to combat problems such as phishing and spyware. This course consists of an entrance exam, three lessons -- each consisting of a webcast, technical paper and quiz -- and a final exam. You'll also find handy checklists that you can download and use on the job. All of these resources are available on-demand so you can learn at your convenience.

   Course Outline
   Entrance Exam
   Begin Lesson 1
   Begin Lesson 2
   Begin Lesson 3
   Final Exam
   About the Instructor

(IE only)
SCHOOL HIGHLIGHTS
Send the editor your feedback on this Security School

Visit our Security School for CISSP training

Visit our SOX Security School

Visit our E-mail Security School

SPONSORED LINKS

thawte white paper:
Building customer confidence with thawte SSL Web server certificates and SuperCerts

  Web Security School Course Outline


Web Security School Entrance Exam
Before you begin Web Security School, take this entrance exam to assess your knowledge of Web security and identify the areas you need to focus on. Make note of your score so you can gauge your progress at the end of the School with our final exam.

TAKE THE EXAM   (Download PDF)


Lesson 1
Learn how to plan and perform a secure installation of your Web server's operating system and services. Michael Cobb also explains detailed hardening procedures and how to secure other network services such as FTP and SMTP, as well as setting up access control and security policies. Finally, you will learn how to set up secure remote management and recovery procedures. After you've attended the webcast and read the technical paper, take the quiz to assess your knowledge of Web server security.


Lesson 2
Learn what to expect and look for when analyzing an attack on your Web server. Michael Cobb presents a guide to logging and auditing leads, as well as a review of essential fortification, countermeasures and other recommended security enhancements for your server. After you've attended the webcast and read the technical paper, take the quiz to assess your knowledge of how to defeat Web server attacks.


Lesson 3
Learn how to plan and implement Web directory structures and permissions, and manage Web development. This lesson includes a primer on secure coding and data management, and procedures for combating phishing, adware and spyware. The accompanying quiz will help you assess your knowledge of securing Web applications.


Final Exam
After you've completed Lessons 1, 2 and 3, take the Web Security School final exam to assess your knowledge of Web security based on what you've learned here.

TAKE THE FINAL EXAM   (Download PDF)

  About the Instructor


Michael Cobb, CISSP-ISSAP is a renowned security author with more than 10 years experience in the IT industry and another 16 years experience in finance. He is the founder and managing director of Cobweb Applications Ltd., a consultancy that offers IT training and support in data security and analysis. He co-authored the book IIS Security and has written numerous technical articles for leading IT publications. Cobb is also a Microsoft Certified Database Administrator and a Microsoft Certified Professional.

  


BROWSE BY TAG
Application and Platform Security,   Web Security Tools and Best Practices,   Web Application Security,   Web Services Security and SOA Security,   Application Attacks (Buffer Overflows, Cross-Site Scripting),   Security Awareness Training and Internal Threats,   Information Security Management,   SSL and TLS VPN Security,   Secure VPN Setup and Configuration,   Enterprise Network Security,   Web Browser Security,   Malware, Viruses, Trojans and Spyware,   Information Security Threats,   Web Server Threats and Countermeasures,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Web Application Security
Black box and white box testing: Which is best?
InZero Systems launches hardware-based security gateway
Web application vulnerability assessment shows patching progress
Preventing SQL injection attacks: A network admin's perspective
Cisco acquires SaaS security vendor ScanSafe
Web application firewall use goes beyond compliance, company finds
Gumblar Trojan drive-by exploits spike following Adobe update
Some Facebook applications lead to Russian attack sites
Barracuda acquires Purewire expanding Web security reach
An enterprise strategy for Web application security threats

Web Services Security and SOA Security
Security testing firm uncovers XML vulnerabilities
Cryptographers say cloud computing can be secured
Information security book excerpts and reviews
Will cloud computing and virtualization save the day?
MySpace, Facebook ignoring basic principles of security
Kaminsky: DNS flaw capable of attacks on many fronts
Kaminsky on DNS rebinding attacks, hacking techniques
Which operating system can best secure an FTP site?
IBM's Watchfire halts network research, focuses on Web apps
How does identity propagation work?

Application Attacks (Buffer Overflows, Cross-Site Scripting)
Quiz: How to build secure applications
Black box and white box testing: Which is best?
Adobe warns of critical update for Reader, Acrobat 9.1.3
9 Ways to Improve Application Security After an Incident
Developers Need Help with Security Errors
Buffer overflow tutorial: How to find vulnerabilities, prevent attacks
SQL injection protection: A guide on how to prevent and stop attacks
Experts rebuke programmers who use SQL injection as feature
SANS: Application threats, website flaws pose biggest security threats
Mozilla helps Adobe push out faster patches
Application Attacks (Buffer Overflows, Cross-Site Scripting) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
anonymous Web surfing  (SearchSecurity.com)
buffer overflow  (SearchSecurity.com)
cache cramming  (SearchSecurity.com)
cookie poisoning  (SearchSecurity.com)
dictionary attack  (SearchSecurity.com)
distributed denial-of-service attack  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
National Computer Security Center  (SearchSecurity.com)
threat modeling  (SearchSecurity.com)
trigraph  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Search Additional Security Research and Solutions
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts